JetBrains Vulnerabilities and Affected Products
Vulnerabilities associated with PyCharm.
Products
Clear product- TeamCity183 vulnerabilities
- YouTrack62 vulnerabilities
- IntelliJ IDEA49 vulnerabilities
- Hub16 vulnerabilities
- Ktor10 vulnerabilities
- GoLand6 vulnerabilities
- Rider6 vulnerabilities
- Toolbox App6 vulnerabilities
- WebStorm6 vulnerabilities
- PyCharm5 vulnerabilities
- PhpStorm4 vulnerabilities
- Junie3 vulnerabilities
- ReSharper2 vulnerabilities
- RubyMine2 vulnerabilities
- Aqua1 vulnerability
- CLion1 vulnerability
- DataGrip1 vulnerability
- Datalore1 vulnerability
- DataSpell1 vulnerability
- dotTrace1 vulnerability
- ETW Host Service1 vulnerability
- IDE Services1 vulnerability
- intellij_idea1 vulnerability
- JetBrains Gateway1 vulnerability
- Kotlin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-65908HIGH | Generated title:JetBrains PyCharm Arbitrary Code Execution via Malicious Python Executable on Untrusted Project OpenIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open CWE-829Jul 23, 2026 | CVSS8.6v3.1 | EPSS0.126% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49384MEDIUM | Generated title:JetBrains PyCharm Stored Cross-Site Scripting in Jupyter Notebook Markdown CellsIn JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible CWE-79May 29, 2026 | CVSS6.1v3.1 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25847HIGH | Generated title:JetBrains PyCharm DOM-based Cross-Site Scripting in Jupyter Viewer PageIn JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible CWE-79Feb 9, 2026 | CVSS8.2v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37051CRITICAL | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7,… CWE-522Jun 10, 2024 | CVSS9.3v3.1 | EPSS3.84% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible | CVSS3.0v3.1 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |